PrivShare

PrivShare security

Don't trust us. Verify us.

PrivShare is designed to minimize the amount you have to trust PrivShare. These pages document what the app protects, what it does not protect, and how a technical user can inspect the browser traffic.

PrivShare is an independent project maintained by Yash Aggarwal.

This first security baseline uses named individual accountability. It does not present PrivShare as operated by a registered company.

What This Baseline Claims

These claims are scoped to implemented share workflows and current repository evidence.

Plaintext stays client-side in normal share workflows

Text, environment-variable payloads, files, share passwords, and private decryption keys are handled in the browser, not by the PrivShare server.

Exact specification over slogans

The cryptography page documents algorithms, parameters, encodings, key transport, and server-visible metadata.

Limitations are part of the model

The threat model calls out compromised devices, malicious browser extensions, copied recipient plaintext, full URL disclosure, and malicious delivered JavaScript.

Responsible disclosure is open

Security researchers can test their own accounts and test shares, then report issues to security@priv-share.com.

What This Baseline Does Not Claim

The absence of these claims is intentional. They are future work or require owner-side verification before public use.

  • No external audit claim.
  • No compliance certification claim.
  • No cash reward program claim.
  • No custom app-level rate limiting claim.
  • No strict script Content-Security-Policy claim.
  • No production observability claim.
  • No company-operated or registered-company claim.
  • No source-map or open-source client-crypto claim yet.